{"id":"CVE-2026-63337","aliases":["GHSA-6g32-pxv4-2wfj"],"url":"https://o3.security/vulnerability/CVE-2026-63337","summary":"RabbitMQ Java client: Unvalidated Class.forName in JSON-RPC ProcedureDescription enables arbitrary class loading","details":"The JSON-RPC tools in `com.rabbitmq.tools.jsonrpc` perform `Class.forName(javaReturnType)` with `initialize=true` on class names received from untrusted AMQP messages, without any validation or allowlist.\n\n**Vulnerable code** (`ProcedureDescription.java:101-127`):\nWhen a `JsonRpcClient` connects, it calls `system.describe` and receives a service description from the AMQP queue. The response JSON includes `javaReturnType` fields that are reflectively set via `JSONUtil.tryFill()`, triggering `setJavaReturnType()` → `computeReturnTypeAsJavaClass()` → `Class.forName(javaReturnType)`.\n\n**Attack scenario:**\n1. Victim uses `JsonRpcClient` to connect to a JSON-RPC service via RabbitMQ\n2. Attacker (co-tenant on shared broker, or MITM) intercepts the `system.describe` request\n3. Attacker responds with crafted `javaReturnType` values\n4. Victim's client calls `Class.forName(attackerInput)` with default `initialize=true`\n5. Static initializers of attacker-specified classes execute in victim's JVM\n\nAdditionally, the loaded class from `getReturnType()` is passed to `mapper.parse(replyStr, expectedType)` at `JsonRpcClient.java:168`, potentially enabling type-confusion.\n\n**Recommended fix:** Use `Class.forName(javaReturnType, false, classLoader)` to prevent static initializer execution, or add an allowlist of permitted return types.\n\n**CWE:** CWE-470\n\n---\n\n**Reply from reporter (2026-06-29):** Thanks for the quick turnaround. Fix looks good. Looking forward to the CVE assignment.","published":"2026-08-18T16:27:09.782Z","modified":"2026-09-20T14:24:10.642473Z","cvss":null,"epss":{"score":0.00317,"percentile":0.23846,"asOf":"2026-08-24"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"com.rabbitmq:amqp-client","fixedVersion":"5.33.0"}],"fix":{"url":"https://github.com/rabbitmq/rabbitmq-java-client/commit/0032f75f9dc3df847f94b2b85a16119250bf63cb","label":"rabbitmq/rabbitmq-java-client@0032f75"},"references":[{"type":"WEB","url":"https://github.com/rabbitmq/rabbitmq-java-client/releases/tag/v5.33.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63337.json"},{"type":"ADVISORY","url":"https://github.com/rabbitmq/rabbitmq-java-client/security/advisories/GHSA-6g32-pxv4-2wfj"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-63337"},{"type":"FIX","url":"https://github.com/rabbitmq/rabbitmq-java-client/commit/0032f75f9dc3df847f94b2b85a16119250bf63cb"},{"type":"FIX","url":"https://github.com/rabbitmq/rabbitmq-java-client/commit/9f8e7efd0c648f235dc0e96232ae7efa75ea4fa8"},{"type":"FIX","url":"https://github.com/rabbitmq/rabbitmq-java-client/pull/2000"},{"type":"FIX","url":"https://github.com/rabbitmq/rabbitmq-java-client/pull/2002"},{"type":"PACKAGE","url":"https://github.com/rabbitmq/rabbitmq-java-client"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-20T14:24:10.642473Z"}}